Social engineering is the practice of manipulating people into performing actions or revealing confidential information, rather than breaking through technology. Attackers exploit reliable human tendencies, including trust, a wish to be helpful, fear, urgency, and deference to authority, to obtain what firewalls and passwords are meant to protect. It is often the cheapest and most effective path into an organization.
The techniques have names worth knowing. Pretexting invents a believable scenario, baiting leaves tempting infected media for someone to plug in, tailgating follows an authorized person through a secured door, and quid pro quo trades a fake favor for access or information. The uncomfortable truth is that social engineering sidesteps technical controls entirely, so the strongest defenses are human, including regular awareness training, clear verification steps for sensitive requests, and a culture where challenging an odd request is welcomed rather than punished.
How is social engineering tested on the CISSP exam?
Social engineering is covered in Domain 1: Security and Risk Management, the largest domain at 16 percent of the exam. Know the main techniques, the psychological levers behind them, and countermeasures including training, policy, and verification.